Managed XDR

generated_email.eml — malware analysis report

File info

Filename
generated_email.eml
File type
news or mail, ASCII text, with CRLF line terminators
File size
6 MB
First seen
Last seen

Environment

w10/x64 en

Hashes

SHA1
c547a93ae9c7cc679c9e8021c58a4ac0ec9d79f7
SHA256
627c52095ebf0d685e10fbe4c764e18fc79bbbfe1f9d0d6ccc1364bc74507b11
MD5
62adf10fa9be233549b6a124f49b968f

Signatures

Persistence

T1547.001 persistence_autorun: Makes itself run automatically on Windows startup
T1574 dropper_dll: Creates DLL, which is then loaded into the process

Privilege Escalation

T1547.001 persistence_autorun: Makes itself run automatically on Windows startup
T1574 dropper_dll: Creates DLL, which is then loaded into the process
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1497 evasion_diskenum: Sandbox evasion using enumeration of partitions
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1574 dropper_dll: Creates DLL, which is then loaded into the process

Discovery

T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1497 evasion_diskenum: Sandbox evasion using enumeration of partitions

Command and Control

T1071.003 network_smtp: Sends emails, possibly SPAM

Other

yara_rules: Static rules
creates_in_windows: Creates files in the Windows directory
copies_self: Creates a copy of itself
network_bind: Starts servers listening at 0.0.0.0:3127, 0.0.0.0:3128, 0.0.0.0:3129, 0.0.0.0:3130, 0.0.0.0:3131, 0.0.0.0:3132, 0.0.0.0:3133, 0.0.0.0:3134, 0.0.0.0:3135, 0.0.0.0:3136, 0.0.0.0:3137, 0.0.0.0:3138, 0.0.0.0:3139, 0.0.0.0:3140, 0.0.0.0:3141, 0.0.0.0:3142, 0.0.0.0:3143, 0.0.0.0:3144, 0.0.0.0:3145, 0.0.0.0:3146, 0.0.0.0:3147, 0.0.0.0:3148, 0.0.0.0:3149, 0.0.0.0:3150, 0.0.0.0:3151, 0.0.0.0:3152, 0.0.0.0:3153, 0.0.0.0:3154, 0.0.0.0:3155, 0.0.0.0:3156, 0.0.0.0:3157, 0.0.0.0:3158, 0.0.0.0:3159, 0.0.0.0:3160, 0.0.0.0:3161, 0.0.0.0:3162, 0.0.0.0:3163, 0.0.0.0:3164, 0.0.0.0:3165, 0.0.0.0:3166, 0.0.0.0:3167, 0.0.0.0:3168, 0.0.0.0:3169, 0.0.0.0:3170, 0.0.0.0:3171, 0.0.0.0:3172, 0.0.0.0:3173, 0.0.0.0:3174, 0.0.0.0:3175, 0.0.0.0:3176, 0.0.0.0:3177, 0.0.0.0:3178, 0.0.0.0:3179, 0.0.0.0:3180, 0.0.0.0:3181, 0.0.0.0:3182, 0.0.0.0:3183, 0.0.0.0:3184, 0.0.0.0:3185, 0.0.0.0:3186, 0.0.0.0:3187, 0.0.0.0:3188, 0.0.0.0:3189, 0.0.0.0:3190, 0.0.0.0:3191, 0.0.0.0:3192, 0.0.0.0:3193, 0.0.0.0:3194, 0.0.0.0:3195, 0.0.0.0:3196, 0.0.0.0:3197, 0.0.0.0:3198, 0.0.0.0:3199
creates_exe: Creates executable files in the file system
network_ftp: Performs FTP requests
has_pdb: This executable file has a PDB path
creates_suspended_process: Creates suspended process
test_check_service: Starts services